Senior Threat Detection Engineer
About the Role
We are looking for a savvy, high-performing Threat Detection Engineer who will be responsible for the day-to-day management of company-wide information security toolsets and the protection of Blackbaud’s and clients’ information. Security Engineers diligently investigate anomalous events and alerts, detect malicious activities, reverse engineer malware, and write signatures and scripts for various security tools to defend against malicious activity. The Security Engineer provides reports to management regarding the negative impact to the business caused by theft, destruction, alteration, or denial of access to information. The role involves analysis, reverse engineering, troubleshooting, and resolution of complex threats impacting information security infrastructure at the data, application, service, operating system, and network levels.
Responsibilities
- Build out automations to optimize team performance and reduce response times
- Document automation building process, including defining pre-build requirements and validation criteria
- Perform intrusion analysis using SIEM technology, reports, data visualization, log analysis, and pattern analysis
- Serve as first responder to security events and escalations via email, phone, and tickets across corporate user networks, data centers, and cloud environments
- Assist in remediation of information security incidents
- Hunt for and identify threat actor groups and their tactics, techniques, and procedures
- Document and communicate findings, escalate critical incidents, and interact with lines of business
- Improve and challenge existing processes and procedures in a fast-paced cybersecurity environment
- Stay current on the threat landscape and cybersecurity trends
- Adapt to fluid infrastructures and learn/support new technologies
- Act as a thought leader around new security alert content creation, data correlation, anomaly thresholds, and logic updates
- Mentor the core analyst team regarding training and escalation
- Serve as a peer reviewer within the core security engineering team
- Advise leadership on optimizing current toolsets and evaluating future tools
Requirements
- 5+ years of Security Engineering and Analysis experience, preferably in Threat Detection and Response
- 5+ years of IT or networking experience
- Intermediate to Advanced Linux/Unix OS and Windows knowledge
- Expertise in at least one public cloud, preferably Microsoft Azure
- Understanding of firewall rule and policy fundamentals
- Network routing fundamentals
- Ability to manage parallel tasks and accurately document resolutions
- Working knowledge of network packet analysis tools
- Proven ability to implement automation through scripting (e.g., PowerShell, PERL, Python, bash scripting)
- Experience leveraging APIs to integrate third-party tooling into an existing tool stack
- Familiarity with cybersecurity frameworks such as NIST and MITRE ATT&CK
- Industry-recognized professional certification such as Security+, CBROPS, CSA, CEH, GSEC, or SSCP
Preferred Qualifications
- CISSP, GBFA, GCDA, GCIA, GCIH, GMON, GNFA, GOSI, GPEN, GPPA, GREM, GSOC, OSDA, or OSCP certification
- Direct experience with malware analysis techniques and methodologies
- Experience with playbook development using Security Orchestration and Automated Response (SOAR) platforms
Pay
The starting base pay is $101,900.00 to $132,800.00. Blackbaud may pay more or less based on employee qualifications, market value, company finances, and other operational considerations.
Benefits
- Medical, dental, and vision insurance
- Remote-flexible workforce
- Wellness programs
- 401(k) program with employer match
- Flexible paid time off
- Generous parental leave
- Donations for Doers
- Pet insurance, legal and identity protection
- Tuition reimbursement program